TrendWhat rose yesterday, every day at 07:30 KST · 한국어

GitHub · as of October 8, 2026 · View on GitHub →

aquasecurity/trivy

Comprehensive security vulnerability scanner

Find hidden security issues in code and containers before deployment

This tool automatically detects vulnerabilities and configuration errors hidden in container images or code repositories right before deployment. Trivy performs broad checks on operating system packages, software dependencies, infrastructure code, and sensitive information. It allows you to handle security checks with a single command, from the development environment to the deployment pipeline.

Inspection targets and items

Trivy inspects container images, file systems, Git repositories, virtual machine images, and Kubernetes clusters. Within these targets, it identifies OS packages and software dependency lists (SBOM), known vulnerabilities (CVE), infrastructure code (IaC) issues and configuration errors, sensitive information and secrets, and software licenses. It supports most popular programming languages, operating systems, and platforms.

Usage and installation

Trivy can be installed through various channels, including Homebrew, Docker, and binary downloads. The basic usage format is trivy <target> [--scanners <scanner1,scanner2>] <subject>. For example, you can check image vulnerabilities with trivy image python:3.4-alpine, or inspect file system vulnerabilities, secrets, and configuration errors with trivy fs --scanners vuln,secret,misconfig myproject/. It integrates with multiple platforms, such as GitHub Actions, Kubernetes operator, and VS Code plugins.

Canary builds and precautions

A Canary build is generated every time a push is made to the main branch. These builds are provided as Docker Hub, GitHub, and ECR images, as well as binaries, but they may contain critical bugs, so their use in production environments is not recommended. For stable usage, it is advisable to use the official release version.

Suitable targets and verification items

This tool is suitable for teams building DevSecOps workflows or automating security checks in container and cloud environments. Before use, verify the scope of supported scanners and targets, and ensure you are using a stable version rather than a Canary build. Trivy is an open-source project by Aqua Security; if you require more features, you can consider the commercial product Aqua.

By the numbers

Language
Go
Topics
containers · devsecops · docker · go · golang · hacktoberfest · iac · infrastructure-as-code
Latest release
v0.75.0 · October 1, 2026
Last commit
October 2, 2026
Open issues
170
Open pull requests
83
Used by
456

Related repositories

Written by AI from this repository's README on October 7, 2026. GitHub's original is the reference.

View on GitHub → · Homepage